This Policy explains what we collect, why, how long we keep it, and who we give it to. The short version: we log calls in detail, we keep those logs, and we hand them over when the law requires it.
This Privacy Policy explains how Machport LLC (“Spoofey”, “we”, “us”), a New Mexico limited liability company with its principal address at 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, USA, collects, uses, shares and retains personal data when you use our website and calling service (the “Service”).
We are the data controller. As a US company we do not operate under one single omnibus privacy statute; our obligations come from applicable US federal law and the state law of wherever you live (including the CCPA/CPRA for California residents — see section 7), and our contact point for privacy matters is privacy@spoofey.com.
Where you are matters more than where we are. Data-protection law generally follows the individual, so if you are in the EEA, the UK, California or another jurisdiction with extraterritorial reach, that law applies to our processing of your data even though we are established in the United States. Where it does, we comply with it and you have the rights set out in section 7. We have not appointed an EU/UK Article 27 representative. If our EEA or UK user base becomes significant, this is a real open item, not an oversight to gloss over.
| Data | Where it comes from |
|---|---|
| Username, email address, hashed password | Sign-up |
| Country, timezone, profile visibility setting | Account settings |
| Registered Number: your own telephone number, which we call to connect you | Required before you can place calls; verified by an automated call or message to that number |
| Identity documents, proof of address, source of funds, or authorisation from a number's subscriber | Not collected for ordinary accounts. Requested only on escalation: risk flags, high spend, disputes, complaints or legal enquiries (see Terms, section 3) |
| Forum posts, direct messages, profile content | Community features |
| Correspondence with support and abuse reports you make | Email and in-product |
Spoofey is a callback bridge: we ring your own number first, then dial the destination and connect the two. That means every call produces records for two legs.
| Leg | What we record |
|---|---|
| First leg: to you | Your Registered Number, the time we dialled it, whether and when you answered, and the duration |
| Second leg: to the destination | The destination number, the caller ID presented, timestamps, duration, disposition, and any failure or block reason |
| Both | Route and carrier used, credits consumed, and the account and IP address that requested the call |
These are call detail records and they are the core of what we hold about you. Note the consequence of the architecture: a verified telephone number that reaches you personally is attached to every call you make.
We do record call audio. We may record and monitor either leg of a call placed through the Service, including any audio carried on it, for the reasons and on the consent basis set out in full in the Terms of Service (section 12), which forms part of this Policy by reference. Recordings are retained for the period set out in the table below, and are accessible only to personnel who need them to operate the Service, investigate abuse, resolve billing disputes, or respond to a valid legal or carrier request.
Payments are processed by third-party providers. We receive the amount, currency, status, timestamp and a transaction or invoice reference. For cryptocurrency payments we also receive the asset and the on-chain transaction identifier, which may be linkable to your wallet and its history by anyone. We do not receive or store full card numbers.
We receive reports and signals from called parties, number subscribers, carriers, industry traceback consortia, regulators, law-enforcement bodies, fraud-prevention and sanctions-screening services, and identity-verification providers.
Where the UK GDPR, EU GDPR or a similar regime applies, we rely on the following bases.
| Purpose | Legal basis |
|---|---|
| Creating and running your account; placing your calls; taking payment; providing support | Performance of a contract |
| Operating the anti-fraud and risk system; enforcing the high-risk number blacklist; detecting and preventing fraud, abuse, harassment and misuse of the Service | Legitimate interests: protecting the public, our carriers and our business from serious harm and legal risk |
| Identity and entitlement verification; sanctions and restricted-party screening | Legal obligation, and legitimate interests |
| Retaining call detail records; responding to traceback requests, regulators, courts and law enforcement | Legal obligation, and legitimate interests |
| Security, logging, monitoring, backup and incident response | Legitimate interests, and legal obligation |
| Service and reliability improvement, aggregate analytics | Legitimate interests |
| Marketing email, where applicable | Consent: withdrawable at any time |
| Establishing, exercising or defending legal claims | Legitimate interests, and legal claims |
Where we rely on legitimate interests we have considered the impact on you. Given the potential for this category of service to be misused to defraud or harass people, we consider comprehensive logging and active risk screening to be necessary and proportionate.
Our anti-fraud risk system automatically evaluates accounts, payments and individual calls, and can automatically decline a call, apply limits, hold a payment, or suspend an account. This can produce legal or similarly significant effects for you.
We carry out this processing because it is necessary for the performance of our contract with you and for compliance with our legal obligations, and because without it the Service could not be operated responsibly. Where you are subject to a significant automated decision and the law gives you the right, you may contact privacy@spoofey.com to request human review, to express your point of view and to contest the decision.
We cannot disclose the specific signals, weights or thresholds, because publishing them would let the system be circumvented by the people it exists to stop.
| Category | Retention |
|---|---|
| Account records | For the life of the account, then 12 months after closure |
| Call detail records | 24 months from the call: long enough to answer traceback and law-enforcement requests, which frequently arrive months after the event |
| Registered Number and its verification record | With the account record, then retained with the call records it is attached to |
| Identity documents, where escalation required them | 5 years after account closure, or as required by anti-money-laundering law |
| Payment and transaction records | 7 years, for tax and accounting purposes |
| Risk, abuse and enforcement records, including records of terminated accounts | Retained on a long-term basis so that banned users can be prevented from returning |
| Messages and forum content | Until deleted by you or by us, plus backup cycle |
| Server and security logs | 90 days |
We may keep data for longer where it is subject to a legal hold, an ongoing investigation, or an actual or anticipated legal claim.
Depending on where you live, you may have the right to access your data; to correct it; to delete it; to restrict or object to processing; to data portability; to withdraw consent; and to complain to a supervisory authority.
To exercise any right, email privacy@spoofey.com from your account address. We may need to verify your identity. We will respond within the period the applicable law requires.
We operate internationally. Our infrastructure is located in the United States and Canada, and your data may be processed there and in any country where a carrier in the call path operates. Calls are by their nature routed across borders, and the destination number and the caller ID you present are necessarily disclosed to carriers in those countries.
The United States is not the subject of a blanket UK or EU adequacy decision (we have not self-certified under the EU-US Data Privacy Framework). Canada, where part of our infrastructure sits, has a standing EU adequacy decision for commercial organisations, but we do not rely on that alone. Where we receive personal data from the UK or EEA we rely on Standard Contractual Clauses or the UK International Data Transfer Addendum, together with a transfer risk assessment and appropriate supplementary measures. You may request a copy of the safeguards from privacy@spoofey.com.
We use encryption in transit, hashed and salted password storage, access controls and least-privilege administration, audit logging, and segregation of verification documents from general account data. We also run automated rate limiting, IP and account ban controls, and an advisory fraud-risk system across the Service to reduce the impact of a compromised account or credential-stuffing attempt.
No system is perfectly secure and we cannot guarantee absolute security. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, you, within the timeframes the law sets.
The Service is not directed to anyone under 18 and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@spoofey.com and we will delete it and close the account.
We may update this Policy. The effective date at the top of the page shows when it last changed, and we will notify you of material changes by email or in-product notice where reasonably practicable.
Privacy enquiries and rights requests: privacy@spoofey.com
Abuse reports and unauthorised presentation of your number: abuse@spoofey.com
Law-enforcement and legal requests: legal@spoofey.com
Questions about this document? Write to legal@spoofey.com. See also the Terms of Service.